# Cisco ISE authentication bypass, CVSS 10, was exploited before the patch

Source: https://startwithidentity.com/blog/2026-09-17-cisco-ise-cvss-10-auth-bypass-exploited-as-a-zero-day/
Last updated: 2026-09-17
License: content by Start with Identity. Cite the source URL.

---

Cisco disclosed CVE-2026-76460, a maximum-severity (CVSS 10.0) flaw in Identity Services Engine (ISE) and ISE Passive Identity Connector, and confirmed it is being exploited in the wild. Insufficient authentication on an API endpoint lets an unauthenticated attacker bypass the web management interface and, per Cisco, obtain command execution as root. Releases 3.1 through 3.5 are affected; the fixes are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7 and 3.5 Patch 4. There is no workaround beyond restricting management traffic with infrastructure access lists. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 16 with a September 19 deadline. Cisco's detection guidance is to search the ISE `ise-kong/access.log` for the username `dummyuser`. It has not said who is exploiting the flaw or how many customers were hit.

## Why it matters

ISE is the policy engine that decides which users and devices get onto the network, over RADIUS and TACACS+. It stores the shared secrets for every switch, wireless controller and VPN concentrator that asks it for a decision, and it is usually joined to Active Directory as an identity source. Root on ISE is therefore not one compromised appliance; it is the ability to rewrite who is allowed on the network and a store of credentials trusted by everything else.

This is the second maximum-severity Cisco management flaw in a week, after the [Secure FMC bypass](https://startwithidentity.com/blog/2026-09-11-cisco-fmc-auth-bypass-feeds-credential-theft-and-qilin/) that attackers used to harvest RADIUS and LDAP bind accounts. The shared lesson is to treat these consoles as tier-zero identity infrastructure: management interfaces reachable only from an admin network, and, after patching, rotation of the RADIUS secrets and directory accounts the box held, because patching closes the door without changing the locks. Cisco's advisory is [cisco-sa-ISE-ABP-VNSW7Tn5](https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ISE-ABP-VNSW7Tn5).

Source: [The Hacker News](https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html)
